Privacy policy

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH places great importance on the responsible and transparent handling of personal data.

Below you will find information about:

  • whom you can contact at GIZ regarding data protection.
  • what data is processed when you visit the website.
  • what data is processed when you contact us, subscribe to newsletters or press releases, or use other GIZ online services.
  • the options available to object to data storage.
  • your rights with respect to us.

1. Data Controller and Data Protection Officer

1. Data Controller and Data Protection Officer
Address:
Friedrich-Ebert-Allee 32 + 36, 53113 Bonn
Dag-Hammarskjöld-Weg 1–5, 65760 Eschborn
Contact:
mirna.mekic@giz.de

If you have specific questions regarding the protection of your data, please contact the GIZ Data Protection Officer at:
datenschutzbeauftragte@giz.de

2. Information on the Collection of Personal Data

2.1 General

GIZ processes personal data exclusively in accordance with the General Data Protection Regulation (GDPR) of the European Union and the German Federal Data Protection Act (BDSG).

Personal data includes, for example, name, address, email address, and user behavior.
Personal data is processed by GIZ only to the extent that is necessary. What data is required and processed, for what purpose, and on what legal basis depends largely on the service you use or the purpose for which the data is needed.

2.2 Collection of Personal Data When Visiting Our Website

When visiting the website digigreen.ba, the browser used automatically transmits certain data that is stored in a log file.

GIZ processes only the data that is technically necessary for the proper display of the website and to ensure its stability and security.
The following information is stored for each access:

  • the page visited,
  • the IP address of the accessing device,
  • the referring page,
  • as well as the date and time of access.

A detailed list of stored data can be found below:

Field: Date
Displayed as: date
Description: The date on which the activity occurred.

Field: Time
Displayed as: time
Description: The time (UTC) when the request was sent to the server.

Field: Client IP Address
Displayed as: c-ip
Description: The IP address of the device that accessed the website.

Field: Request Method
Displayed as: cs-method
Description: The HTTP method used (e.g., GET, POST).

Field: URI (Resource)
Displayed as: cs-uri-stem
Description: The file or page path the client attempted to access.

Field: URI Query
Displayed as: cs-uri-query
Description: The URL query string containing parameters, if any; often empty.

Field: HTTP Status
Displayed as: sc-status
Description: The status code returned by the server (e.g., 200 = success, 301 = redirect).

Field: User Agent
Displayed as: cs(User-Agent)
Description: Information about the browser and device used by the visitor.

Field: Referrer
Displayed as: cs(Referrer)
Description: The URL of the page from which the user arrived (if applicable).

Field: Protocol
Displayed as: protocol
Description: The version of the TLS/SSL protocol used for communication (e.g., TLSv1.3).

Field: Request Duration
Displayed as: time-taken
Description: The time (in seconds or milliseconds) it took for the server to process the request.

Field: Server IP Address
Displayed as: s-ip
Description: The IP address of the server that processed the request.

Field: Hostname
Displayed as: host
Description: The domain name to which the request was made (e.g., digigreen.ba).

Field: HTTP Version
Displayed as: http-version
Description: The version of the HTTP protocol used in the request (e.g., HTTP/1.1, HTTP/2.0).

Field: Additional Statuses
Displayed as: sc-substatus, sc-win32-status, cache-status, upstream-status
Description: Various technical codes indicating caching, proxy status, errors, or special processing conditions.

2.3 Website Usage Data Analysis

To analyze the use of its website, GIZ uses the web analytics service Matomo, operated by InnoCraft Ltd, Wellington, New Zealand. The data is stored and processed entirely anonymously.

The data generated via the Matomo system is processed and stored on behalf of GIZ exclusively in Europe and New Zealand.

More information about Matomo’s data protection policies can be found here:
Matomo Cloud Privacy Policy – Matomo Analytics

Additional Information on User Analysis

Matomo uses cookies to enable statistical analysis of the use of GIZ’s website.

The cookies used by Matomo do not contain any information that can identify users.

Each time you visit the GIZ website or download a file, the information about that activity is processed and stored in a temporary log file. Before being stored, every data set is anonymized by modifying the IP address.

GIZ uses this information for statistical purposes within its public relations work and to provide information tailored to users’ needs, in accordance with its mandate.

Legal basis: Article 6(1)(e) GDPR in conjunction with Section 3 of the BDSG.

Opt-Out Information

Users who do not agree with the fully anonymous storage and analysis of data regarding their website visits may opt out at any time by clicking the appropriate button.

The opt-out button is located at the bottom of the page.

Additional Notes on Opt-Out

An “opt-out cookie” is then saved to the user’s device to prevent data collection during visits to the relevant website.

For the opt-out to be effective, the cookie must be stored on each device used and in each browser (e.g., Microsoft Edge, Chrome, Mozilla Firefox).

If all cookies on the device are deleted, the opt-out cookie is also deleted and must be reactivated.

3. Processing of Personal Data When Contacting Us

When users contact us, the data provided is processed in order to respond to the inquiry.

The following means of contact are available:

  • contact form
  • email

3.1 Contact Form

A contact form is available on our website for electronic communication.

When using the contact form, the following data is processed: [e.g., title, last name, first name, email address], as well as any other personal data entered in the message.

Postal address and other information provided may also be processed. Providing a postal address is not mandatory, but it enables a reply by post if given.

The processing of this data is based on consent under Article 6(1)(a) GDPR and is done for the purpose of responding to the user’s request.

By ticking the checkbox and submitting the form, the user consents to the transfer and storage of their personal data. The form can be cancelled at any time before submission. Data is only transmitted once the form is submitted.

The transfer of data to GIZ is done via an SSL-encrypted connection.

3.2 Contact via Email

Alternatively, users can contact GIZ via the provided email addresses. In this case, at a minimum, the email address is stored, along with all other personal data the user provides in the message (e.g., name, address), and the content of the email itself – solely for the purpose of processing the request and responding.
Legal basis: Article 6(1)(e) GDPR.

Legal basis: Article 6(1)(e) GDPR.

4. Processing of Personal Data via Social Media Platforms

On its website, GIZ provides links to its official profiles on social networks such as LinkedIn, YouTube, and Facebook.

These online profiles serve to interact with users active on those platforms and to provide information about GIZ’s work and services. Clicking on a social media logo redirects users to the respective GIZ profile.

When users visit those platforms, personal data is collected, used, and stored by the platform operators – not by GIZ. This applies even if the user does not have an account with the platform.

The specific data processing activities and their scope vary by provider. GIZ has no influence over the collection or further use of data by these platforms.

GIZ does not know:

  • the extent of the data collected,
  • the exact locations where it is processed,
  • how long it is stored,
  • the platforms’ compliance with deletion obligations,
  • what analyses are performed,
  • how data is linked,
  • or with whom the data is shared.

When accessing GIZ’s social media pages, the terms of use and privacy policies of the respective platforms apply.

GIZ’s Social Media Profiles:

Note on GIZ’s Facebook Page (“Fan Page”)

When visiting GIZ’s Facebook pages, Facebook collects your IP address and other information via cookies. These are used to generate statistical reports for GIZ via Facebook Insights.

These reports are created solely by Facebook. GIZ has no control over how data is generated or displayed. This functionality is automatic and cannot be disabled.

GIZ uses its Facebook page as a modern tool for communication and public outreach.

Legal basis: Article 6(1)(e) GDPR.

As the page administrator, GIZ shares responsibility for data processing with Facebook. However, Facebook assumes primary responsibility for Insight data. Facebook is also responsible for complying with all GDPR obligations related to that data (Articles 12, 13, 15–22, and 32–34).

User rights can be exercised through both GIZ and Facebook. If you contact GIZ, we are obliged to forward relevant information to Facebook.

The full Joint Controller Addendum regarding Facebook Insights is available here:
https://www.facebook.com/legal/terms/page_controller_addendum

5. Disclosure of Data to Third Parties

GIZ does not pass on personal data to third parties unless it is legally required or authorized to do so.

6. Transfer of Data to Third Countries

GIZ does not transfer personal data to third countries.
When using social media platforms, the data protection regulations of the respective providers apply.

7. Data Retention Period

User data is not retained any longer than necessary for the intended purpose or as required by law.

8. IT Security of User Data

The protection of personal data is of great importance to GIZ. Technical and organizational security measures are implemented to safeguard the data from accidental or intentional manipulation, accidental deletion, and unauthorized access.

These measures are continuously updated in accordance with technological advancements and evolving risks.

9. User Rights

Visitors to GIZ’s website have the following rights:

  • Access to their stored personal data (Article 15 GDPR),
  • Rectification of their data (Article 16 GDPR),
  • Erasure of their data (Article 17 GDPR),
  • Restriction of data processing (Article 18 GDPR),
  • Objection to data processing (Article 21 GDPR),
  • Data portability – the right to receive their data in a standard and machine-readable format and transfer it to another controller (Article 20 GDPR),
  • Withdrawal of consent if the processing was based on consent (Article 6(1)(a) GDPR). Withdrawal does not affect the lawfulness of data processing carried out prior to the withdrawal.

In accordance with Article 77 GDPR, you have the right to lodge a complaint with the competent supervisory authority for data protection.

The responsible authority for GIZ is the Federal Commissioner for Data Protection and Freedom of Information (BfDI).

If you have any questions regarding the processing of your personal data, you may contact the GIZ Data Protection Officer at:
datenschutzbeauftragte@giz.de

Date of last update: April 1, 2025

The program is jointly financed by:

Logotipi EU i Švicarske Logotipi BMZ i GiZ